Global Guidance for Local Generalization in Model Checking

SMT-based model checkers, especially IC3-style ones, are currently the most effective techniques for verification of infinite state systems. They infer global inductive invariants via local reasoning about a single step of the transition relation of a system, while employing SMT-based procedures, such as interpolation, to mitigate the limitations of local reasoning and allow for better generalization. Unfortunately, these mitigations intertwine model checking with heuristics of the underlying SMT-solver, negatively affecting stability of model checking. In this paper, we propose to tackle the limitations of locality in a systematic manner. We introduce explicit global guidance into the local reasoning performed by IC3-style algorithms. To this end, we extend the SMT-IC3 paradigm with three novel rules, designed to mitigate fundamental sources of failure that stem from locality. We instantiate these rules for the theory of Linear Integer Arithmetic and implement them on top of Spacer solver in Z3. Our empirical results show that GSpacer, Spacer extended with global guidance, is significantly more effective than both Spacer and sole global reasoning, and, furthermore, is insensitive to interpolation.


Introduction
SMT-based Model Checking algorithms that combine SMT-based search for bounded counterexamples with interpolation-based search for inductive invariants are currently the most effective techniques for verification of infinite state systems.They are widely applicable, including for verification of synchronous systems, protocols, parameterized systems, and software.
The Achilles heel of these approaches is the mismatch between the local reasoning used to establish absence of bounded counterexamples and a global reason for absence of unbounded counterexamples (i.e., existence of an inductive invariant).This is particularly apparent in IC3-style algorithms [7], such as SPACER [18].IC3-style algorithms establish bounded safety by repeatedly computing predecessors of error (or bad) states, blocking them by local reasoning about a single step of the transition relation of the system, and, later, using the resulting lemmas to construct a candidate inductive invariant for the global safety proof.The whole process is driven by the choice of local lemmas.Good lemmas lead to quick convergence, bad lemmas make even simple-looking problems difficult to solve.
The effect of local reasoning is somewhat mitigated by the use of interpolation in lemma construction.In addition to the usual inductive generalization by dropping literals from a blocked bad state, interpolation is used to further generalize the blocked state using theory-aware reasoning.For example, when blocking a bad state x = 1 ∧ y = 1, inductive generalization would infer a sub-clause of x = 1 ∨ y = 1 as a lemma, while interpolation might infer x = y -a predicate that might be required for the inductive invariant.SPACER, that is based on this idea, is extremely effective, as demonstrated by its performance in recent CHC-COMP competitions [10].The downside, however, is that the approach leads to a highly unstable procedure that is extremely sensitive to syntactic changes in the system description, changes in interpolation algorithms, and any algorithmic changes in the underlying SMT-solver.
An alternative approach, often called invariant inference, is to focus on the global safety proof, i.e., an inductive invariant.This has long been advocated by such approaches as Houdini [15], and, more recently, by a variety of machine-learning inspired techniques, e.g., FreqHorn [14], LinearArbitrary [28], and ICE-DT [16].The key idea is to iteratively generate positive (i.e., reachable states) and negative (i.e., states that reach an error) examples and to compute a candidate invariant that separates these two sets.The reasoning is more focused towards the invariant, and, the search is restricted by either predicates, templates, grammars, or some combination.Invariant inference approaches are particularly good at finding simple inductive invariants.However, they do not generalize well to a wide variety of problems.In practice, they are often used to complement other SMT-based techniques.
In this paper, we present a novel approach that extends, what we call, local reasoning of IC3-style algorithms with global guidance inspired by the invariant inference algorithms described above.Our main insight is that the set of lemmas maintained by IC3-style algorithms hint towards a potential global proof.However, these hints are lost in existing approaches.We observe that letting the current set of lemmas, that represent candidate global invariants, guide local reasoning by introducing new lemmas and states to be blocked is often sufficient to direct IC3 towards a better global proof.
We present and implement our results in the context of SPACER -a solver for Constrained Horn Clauses (CHC) -implemented in the Z3 SMT-solver [13].SPACER is used by multiple software model checking tools, performed remarkably well in CHC-COMP competitions [10], and is open-sourced.However, our results are fundamental and apply to any other IC3-style algorithm.While our implementation works with arbitrary CHC instances, we simplify the presentation by focusing on infinite state model checking of transition systems.
We illustrate the pitfalls of local reasoning using three examples shown in Fig. 1.All three examples are small, simple, and have simple inductive invariants.All three are challenging for SPACER.Where these examples are based on SPACER-specific design choices, each exhibits a fundamental deficiency that stems from local reasoning.We believe they can be adapted for any other IC3-style verification algorithm.The examples assume basic familiarity with the IC3 paradigm.Readers who are not familiar with it may find it useful to read the examples after reading Sec. 2. where a, b, c, d are the program variables.These lemmas establish that there are no counterexamples of longer and longer lengths.However, the process never converges to the desired lemma (a−c) ≤ (b−d), which excludes counterexamples of any length.The lemmas are discovered using interpolation, based on proofs found by the SMT-solver.A close examination of the corresponding proofs shows that the relationship between (a − c) and (b − d) does not appear in the proofs, making it impossible to find the desired lemma by tweaking local interpolation reasoning.On the other hand, looking at the global proof (i.e., the set of lemmas discovered to refute a bounded counterexample), it is almost obvious that (a − c) ≤ (b − d) is an interesting generalization to try.Amusingly, a small, syntactic, but semantic preserving change of swapping line 2 for line 3 in Fig. 1(a) changes the SMT-solver proofs, affects local interpolation, and makes the instance trivial for SPACER.

Myopic generalization. SPACER diverges on the example in
Excessive (predecessor) generalization.SPACER diverges on the example in Fig. 1(b) by computing an infinite sequence of lemmas of the form a + k 1 × b ≥ k 2 , where a and b are program variables, and k 1 and k 2 are integers.The root cause is excessive generalization in predecessor computation.The Bad states are a < 0, and their predecessors are states such as (a = 1 ∧ b = −10), (a = 2 ∧ b = −10), etc., or, more generally, regions (a + b < 0), (a + 2b < −1), etc. SPACER always attempts to compute the most general predecessor states.This is the best local strategy, but blocking these regions by learning their negation leads to the aforementioned lemmas.According to the global proof these lemmas do not converge to a linear invariant.An alternative strategy that under-approximates the problematic regions by (numerically) simpler regions and, as a result, learns simpler lemmas is desired (and is effective on this example).For example, region a + 3b ≤ −4 can be under-approximated by a ≤ 32 ∧ b ≤ −12, eventually leading to a lemma b ≥ 0, that is a part of the final invariant: Stuck in a rut.Finally, SPACER converges on the example in Fig. 1(c), but only after unrolling the system for 100 iterations.During the first 100 iterations, SPACER learns that program states with (a ≥ 100 ∧ b = c) are not reachable because a is bounded by 1 in the first iteration, by 2 in the second, and so on.In each iteration, the global proof is updated by replacing a lemma of the form a < k by lemma of the form a < (k + 1) for different values of k.Again, the strategy is good locally -total number of lemmas does not grow and the bounded proof is improved.Yet, globally, it is clear that no progress is made since the same set of bad states are blocked again and again in slightly different ways.An alternative strategy is to abstract the literal a ≥ 100 from the formula that represents the bad states, and, instead, conjecture that no states in b = c are reachable.Our approach: global guidance.As shown in the examples above, in all the cases that SPACER diverges, the missteps are not obvious locally, but are clear when the overall proof is considered.We propose three new rules, Subsume, Concretize, and, Conjecture, that provide global guidance, by considering existing lemmas, to mitigate the problems illustrated above.Subsume introduces a lemma that generalizes existing ones, Concretize under-approximates partially-blocked predecessors to focus on repeatedly unblocked regions, and Conjecture over-approximates a predecessor by abstracting away regions that are repeatedly blocked.The rules are generic, and apply to arbitrary SMT theories.Furthermore, we propose an efficient instantiation of the rules for the theory Linear Integer Arithmetic.
We have implemented the new strategy, called GSPACER, in SPACER and compared it to the original implementation of SPACER.We show that GSPACER outperforms SPACER in benchmarks from CHC-COMP 2018 and 2019.More significantly, we show that the performance is independent of interpolation.While SPACER is highly dependent on interpolation parameters, and performs poorly when interpolation is disabled, the results of GSPACER are virtually unaffected by interpolation.We also compare GSPACER to LinearArbitrary [28], a tool that infers invariants using global reasoning.GSPACER outperforms LinearArbitrary on the benchmarks from [28].These results indicate that global guidance mitigates the shortcomings of local reasoning.
The rest of the paper is structured as follows.Sec. 2 presents the necessary background.Sec. 3 introduces our global guidance as a set of abstract inference rules.Sec. 4 describes an instantiation of the rules to Linear Integer Arithmetic (LIA).Sec. 5 presents our empirical evaluation.Finally, Sec. 7 describes related work and concludes the paper.

Background
Logic.We consider first order logic modulo theories, and adopt the standard notation and terminology.A first-order language modulo theory T is defined over a signature Σ that consists of constant, function and predicate symbols, some of which may be interpreted by T .As always, terms are constant symbols, variables, or function symbols applied to terms; atoms are predicate symbols applied to terms; literals are atoms or their negations; cubes are conjunctions of literals; and clauses are disjunctions of literals.Unless otherwise stated, we only consider closed formulas (i.e., formulas without any free variables).As usual, we use sets of formulas and their conjunctions interchangeably.MBP.Given a set of constants v, a formula ϕ and a model M |= ϕ, Model Based Projection (MBP) of ϕ over the constants v, denoted MBP(v, ϕ, M ), computes a modelpreserving under-approximation of ϕ projected onto Σ \ v.That is, MBP(v, ϕ, M ) is a formula over Σ \ v such that M |= MBP(v, ϕ, M ) and any model M |= MBP(v, ϕ, M ) can be extended to a model M |= ϕ by providing an interpretation for v.There are polynomial time algorithms for computing MBP in Linear Arithmetic [18,5].Interpolation.Given an unsatisfiable formula A ∧ B, an interpolant, denoted ITP(A, B), is a formula I over the shared signature of A and B such that A ⇒ I and I ⇒ ¬B.Safety problem.A transition system is a pair Init, Tr , where Init is a formula over Σ and Tr is a formula over Σ ∪ Σ , where Σ = {s | s ∈ Σ}. 4 The states of the system correspond to structures over Σ, Init represents the initial states and Tr represents the transition relation, where Σ is used to represent the pre-state of a transition, and Σ is used to represent the post-state.For a formula ϕ over Σ, we denote by ϕ the formula obtained by substituting each s ∈ Σ by s ∈ Σ .A safety problem is a triple Init, Tr , Bad , where Init, Tr is a transition system and Bad is a formula over Σ representing a set of bad states.
The safety problem Init, Tr , Bad has a counterexample of length k if the following formula is satisfiable: where ϕ i is defined over Σ i = {s i | s ∈ Σ} (a copy of the signature used to represent the state of the system after the execution of i steps) and is obtained from ϕ by substituting each s ∈ Σ by s i ∈ Σ i , and Tr i is obtained from Tr by substituting s ∈ Σ by s i ∈ Σ i and s ∈ Σ by s i+1 ∈ Σ i+1 .The transition system is safe if the safety problem has no counterexample, of any length.Inductive invariants.An inductive invariant is a formula Inv over Σ such that (i) Init ⇒ Inv , (ii) Inv ∧ Tr ⇒ Inv , and (iii) Inv ⇒ ¬Bad .If such an inductive invariant exists, then the transition system is safe.Spacer.The safety problem defined above is an instance of a more general problem, CHC-SAT, of satisfiability of Constrained Horn Clauses (CHC).SPACER is a semidecision procedure for CHC-SAT.However, to simplify the presentation, we describe the algorithm only for the particular case of the safety problem.We stress that SPACER, as well as the developments of this paper, apply to the more general setting of CHCs (both linear and non-linear).We assume that the only uninterpreted symbols in Σ are constant symbols, which we denote x.Typically, these represent program variables.Without loss of generality, we assume that Bad is a cube.
Alg. 1 presents the key ingredients of SPACER as a set of guarded commands (or rules).It maintains the following.Current unrolling depth N at which a counterexample is searched (there are no counterexamples with depth less than N ).A trace O = (O 0 , O 1 , . ..) of frames, such that each frame O i is a set of lemmas, and each lemma ∈ O i is a clause.A queue of proof obligations Q, where each proof obligation (POB) in Q is a pair ϕ, i of a cube ϕ and a level number i, 0 ≤ i ≤ N .An under-approximation U of reachable states.Intuitively, each frame O i is a candidate inductive invariant s.t.O i over-approximates states reachable up to i steps from Init.The latter is ensured since O 0 = Init, the trace is monotone, i.e., O i+1 ⊆ O i , and each frame is inductive relative to its previous one, i.e., O i ∧ Tr ⇒ O i+1 .Each POB ϕ, i in Q corresponds to a suffix of a potential counterexample that has to be blocked in O i , i.e., has to be proven unreachable in i steps.
The Candidate rule adds an initial POB Bad , N to the queue.If a POB ϕ, i cannot be blocked because ϕ is reachable from frame (i − 1), the Predecessor rule generates a predecessor ψ of ϕ using MBP and adds ψ, i − 1 to Q.The Successor rule updates the set of reachable states if the POB is reachable.If the POB is blocked, the Conflict rule strengthens the trace O by using interpolation to learn a new lemma that blocks the POB, i.e., implies ¬ϕ.The Induction rule strengthens a lemma by Algorithm 1: SPACER algorithm as a set of guarded commands.We use the shorthand function SPACER: In: Init, Tr , Bad Out: safe, Inv or unsafe Algorithm 2: Global guidance rules for SPACER.
inductive generalization and the Propagate rule pushes a lemma to a higher frame.If the Bad state has been blocked at N , the Unfold rule increments the depth of unrolling N .In practice, the rules are scheduled to ensure progress towards finding a counterexample.

Global guidance of local proofs
As illustrated by the examples in Fig. 1, while SPACER is generally effective, its local reasoning is easily confused.The effectiveness is very dependent on the local computation of predecessors using model-based projection, and lemmas using interpolation.
In this section, we extend SPACER with three additional global reasoning rules.The rules are inspired by the deficiencies illustrated by the motivating examples in Fig. 1.
In this section, we present the rules abstractly, independent of any underlying theory, focusing on pre-and post-conditions.In Sec. 4, we specialize the rules for Linear Integer Arithmetic, and show how they are scheduled with the other rules of SPACER in an efficient verification algorithm.The new global rules are summarized in Alg. 2. We use the same guarded command notation as in description of SPACER in Alg. 1.Note that the rules supplement, and not replace, the ones in Alg. 1. Subsume is the most natural rule to explain.It says that if there is a set of lemmas L at level i, and there exists a formula ψ such that (a) ψ is stronger than every lemma in L, and (b) ψ over-approximates states reachable in at most k steps, where k ≥ i, then ψ can be added to the trace to subsume L. This rule reduces the size of the global proof -that is, the number of total not-subsumed lemmas.Note that the rule allows ψ to be at a level k that is higher than i.The choice of ψ is left open.The details are likely to be specific to the theory involved.For example, when instantiated for LIA, Subsume is sufficient to solve example in Fig. 1(a).Interestingly, Subsume is not likely to be effective for propositional IC3.In that case, ψ is a clause and the only way for it to be stronger than L is for ψ to be a syntactic sub-sequence of every lemma in L, but such ψ is already explored by local inductive generalization (rule Induction in Alg. 1).
Concretize applies to a POB, unlike Subsume.It is motivated by example in Fig. 1(b) that highlights the problem of excessive local generalization.SPACER always computes as general predecessors as possible.This is necessary for refutational completeness since in an infinite state system there are infinitely many potential predecessors.Computing the most general predecessor ensures that SPACER finds a counterexample, if it exists.However, this also forces SPACER to discover more general, and sometimes more complex, lemmas than might be necessary for an inductive invariant.Without a global view of the overall proof, it is hard to determine when the algorithm generalizes too much.The intuition for Concretize is that generalization is excessive when there is a single POB ϕ, j that is not blocked, yet, there is a set of lemmas L such that every lemma ∈ L partially blocks ϕ.That is, for any ∈ L, there is a sub-region ϕ of POB ϕ that is blocked by (i.e., ⇒ ¬ϕ ), and there is at least one state s ∈ ϕ that is not blocked by any existing lemma in L (i.e., s |= ϕ ∧ L).In this case, Concretize computes an under-approximation γ of ϕ that includes some not-yet-blocked state s.
The new POB is added to the lowest level at which γ is not yet blocked.Concretize is useful to solve the example in Fig. 1(b).
Conjecture guides the algorithm away from being stuck in the same part of the search space.A single POB ϕ might be blocked by a different lemma at each level that ϕ appears in.This indicates that the lemmas are too strong, and cannot be propagated successfully to a higher level.The goal of the Conjecture rule is to identify such a case to guide the algorithm to explore alternative proofs with a better potential for generalization.This is done by abstracting away the part of the POB that has been blocked in the past.The pre-condition for Conjecture is the existence of a POB ϕ, j such that ϕ is split into two (not necessarily disjoint) sets of literals, α and β.Second, there must be a set of lemmas L, at a (typically much lower) level i < j such that every lemma ∈ L blocks ϕ, and, moreover, blocks ϕ by blocking β.Intuitively, this implies that while there are many different lemmas (i.e., all lemmas in L) that block ϕ at different levels, all of them correspond to a local generalization of ¬β that could not be propagated to block ϕ at higher levels.In this case, Conjecture abstracts the POB ϕ into α, hoping to generate an alternative way to block ϕ.Of course, α is conjectured only if it is not already blocked and does not contain any known reachable states.Conjecture is necessary for a quick convergence on the example in Fig. 1(c).In some respect, Conjecture is akin to widening in Abstract Interpretation [12] -it abstracts a set of states by dropping constraints that appear to prevent further exploration.Of course, it is also quite different since it does not guarantee termination.While Conjecture is applicable to propositional IC3 as well, it is much more significant in SMT-based setting since in many FOL theories a single literal in a POB might result in infinitely many distinct lemmas.Each of the rules can be applied by itself, but they are most effective in combination.For example, Concretize creates less general predecessors, that, in the worst case, lead to many simple lemmas.At the same time, Subsume combines lemmas together into more complex ones.The interaction of the two produces lemmas that neither one can produce in isolation.At the same time, Conjecture helps unstuck the algorithm from a single unproductive POB, allowing the other rules to take effect.

Global guidance for Linear Integer Arithmetic
In this section, we present a specialization of our general rules, shown in Alg. 2, to the theory of Linear Integer Arithmetic (LIA).This requires solving two problems: identifying subsets of lemmas for pre-conditions of the rules (clearly using all possible subsets is too expensive), and applying the rule once its pre-condition is met.For lemma selection, we introduce a notion of syntactic clustering based on anti-unification.For rule application, we exploit basic properties of LIA for an effective algorithm.Our presentation is focused on LIA exclusively.However, the rules extend to combinations of LIA with other theories, such as the combined theory of LIA and Arrays.
The rest of this section is structured as follows.We begin with a brief background on LIA in Sec.4.1.We then present our lemma selection scheme, which is common to all the rules, in Sec.4.2, followed by a description of how the rules Subsume (in Sec.4.3), Concretize (in Sec.4.4), and Conjecture (in Sec.4.5) are instantiated for LIA.We conclude in Sec.4.6 with an algorithm that integrates all the rules together.

Linear Integer Arithmetic: Background
In the theory of Linear Integer Arithmetic (LIA), formulas are defined over a signature that includes interpreted function symbols +, −, ×, interpreted predicate symbols <, ≤, |, interpreted constant symbols 0, 1, 2, . .., and uninterpreted constant symbols a, b, . . ., x, y, . ... We write Z for the set interpreted constant symbols, and call them integers.We use constants to refer exclusively to the uninterpreted constants (these are often called variables in LIA literature).Terms (and accordingly formulas) in LIA are restricted to be linear, that is, multiplication is never applied to two constants.
We write LIA −div for the fragment of LIA that excludes divisiblity (d | h) predicates.A literal in LIA −div is a linear inequality; a cube is a conjunction of such inequalities, that is, a polytope.We find it convenient to use matrix-based notation for representing cubes in LIA −div .A ground cube c ∈ LIA −div with p inequalities (literals) over k (uninterpreted) constants is written as T is a column vector that consists of the (uninterpreted) constants, and In the sequel, all vectors are column vectors, superscript T denotes transpose, dot is used for a dot product and [n 1 ; n 2 ] stands for a matrix of column vectors n 1 and n 2 .

Lemma selection
A common pre-condition for all of our global rules in Alg. 2 is the existence of a subset of lemmas L of some frame O i .Attempting to apply the rules for every subset of O i is infeasible.In practice, we use syntactic similarity between lemmas as a predictor that one of the global rules is applicable, and restrict L to subsets of syntactically similar lemmas.In the rest of this section, we formally define what we mean by syntactic similarity, and how syntactically similar subsets of lemmas, called clusters, are maintained efficiently throughout the algorithm.Syntactic similarity.A formula π with free variables is called a pattern.Note that we do not require π to be in LIA.Let σ be a substitution, i.e., a mapping from variables to terms.We write πσ for the result of replacing all occurrences of free variables in π with their mapping under σ.A substitution σ is called numeric if it maps every variable to an integer, i.e., the range of σ is Z.We say that a formula ϕ numerically matches a pattern π iff there exists a numeric substitution σ such that ϕ = πσ.Note that, as usual, the equality is syntactic.For example, consider the pattern π = v 0 a + v 1 b ≤ 0 with free variables v 0 and v 1 and uninterpreted constants a and b.The formula ϕ 1 = 3a + 4b ≤ 0 matches π via a numeric substitution σ 1 = {v 0 → 3, v 1 → 4}.However, ϕ 2 = 4b + 3a ≤ 0, while semantically equivalent to ϕ 1 , does not match π.Similarly ϕ 3 = a + b ≤ 0 does not match π as well.
Matching is extended to patterns in the usual way by allowing a substitution σ to map variables to variables.We say that a pattern π 1 is more general than a pattern π 2 if π 2 matches π 1 .A pattern π is a numeric anti-unifier for a pair of formulas ϕ 1 and ϕ 2 if both ϕ 1 and ϕ 2 match π numerically.We write anti(ϕ 1 , ϕ 2 ) for a most general numeric anti-unifier of ϕ 1 and ϕ 2 .We say that two formulas ϕ 1 and ϕ 2 are syntactically similar if there exists a numeric anti-unifier between them (i.e., anti(ϕ 1 , ϕ 2 ) is defined).Anti-unification is extended to sets of formulas in the usual way.Clusters.We use anti-unification to define clusters of syntactically similar formulas.Let Φ be a fixed set of formulas, and π a pattern.A cluster, C Φ (π), is a subset of Φ such that every formula ϕ ∈ C Φ (π) numerically matches π.That is, π is a numeric anti-unifier for C Φ (π).In the implementation, we restrict the pre-conditions of the global rules so that a subset of lemmas L ⊆ O i is a cluster for some pattern π, i.e., L = C Oi (π).Clustering lemmas.We use the following strategy to efficiently keep track of available clusters.Let new be a new lemma to be added to O i .Assume there is at least one lemma ∈ O i that numerically anti-unifies with new via some pattern π.If such an does not belong to any cluster, a new cluster C Oi (π) = { new , } is formed, where π = anti( new , ).Otherwise, for every lemma ∈ O i that numerically matches new and every cluster C Oi (π) containing , new is added to C Oi (π) if new matches π, or a new cluster is formed using , new , and any other lemmas in C Oi (π) that anti-unify with them.Note that a new lemma new might belong to multiple clusters.
For example, suppose new = (a ≤ 6 ∨ b ≤ 6), and there is already a cluster Since new anti-unifies with each of the lemmas in the cluster, but does not match the pattern a ≤ v 0 ∨ b ≤ 5, a new cluster that includes all of them is formed w.r.t. a more general pattern: In the presentation above, we assumed that anti-unification is completely syntactic.This is problematic in practice since it significantly limits the applicability of the global rules.Recall, for example, that a + b ≤ 0 and 2a + 2b ≤ 0 do not anti-unify numerically according to our definitions, and, therefore, do not cluster together.In practice, we augment syntactic anti-unification with simple rewrite rules that are applied greedily.For example, we normalize all LIA terms, take care of implicit multiplication by 1, and of associativity and commutativity of addition.In the future, it is interesting to explore how advanced anti-unification algorithms, such as [8,27], can be adapted for our purpose.

Subsume rule for LIA
Recall that the Subsume rule (Alg.2) takes a cluster of lemmas L = C Oi (π) and computes a new lemma ψ that subsumes all the lemmas in L, that is ψ ⇒ L. We find it convenient to dualize the problem.Let S = {¬ | ∈ L} be the dual of L, clearly ψ ⇒ L iff ( S) ⇒ ¬ψ.Note that L is a set of clauses, S is a set of cubes, ψ is a clause, and ¬ψ is a cube.In the case of LIA −div , this means that S represents a union of convex sets, and ¬ψ represents a convex set that the Subsume rule must find.The strongest such ¬ψ in LIA −div exists, and is the convex closure of S. Thus, applying Subsume in the context of LIA −div is reduced to computing a convex closure of a set of (negated) lemmas in a cluster.Full LIA extends LIA −div with divisibility constraints.Therefore, Subsume obtains a stronger ¬ψ by adding such constraints.Example 1.For example, consider the following cluster: However, a stronger over-approximation exists in LIA: In the sequel, we describe SUBSUMECUBE (Alg.3) which computes a cube ϕ that over-approximates ( S). Subsume is then implemented by removing from L lemmas that are already subsumed by existing lemmas in L, dualizing the result into S, invoking SUBSUMECUBE on S and returning ¬ϕ as a lemma that subsumes L.
Recall that Subsume is tried only in the case L = C Oi (π).We further require that the negated pattern, ¬π, is of the form A • x ≤ v, where A is a coefficients matrix, x is a vector of constants and v = (v 1 • • • v p ) T is a vector of p free variables.Under this assumption, S (the dual of L) is of the form {(A • x ≤ n i ) | 1 ≤ i ≤ q}, where q = |S|, and for each 1 ≤ i ≤ q, n i is a numeric substitution to v from which one of the negated lemmas in S is obtained.That is, . Thus, computing the over-approximation of S is reduced to (a) computing the convex hull H of a set of points {n i | 1 ≤ i ≤ q}, (b) computing divisibility constraints D that are satisfied by all the points, (c) substituting H ∧ D for the disjunction in the equation above, and (c) eliminating variables v.Both the computation of H ∧ D and the elimination of v may be prohibitively expensive.We, therefore, over-approximate them.Our approach for doing so is presented in Alg. 3, and explained in detail below.Computing the convex hull of {n i | 1 ≤ i ≤ q}.lines 3 to 8 compute the convex hull of {n i | 1 ≤ i ≤ q} as a formula over v, where variable v j , for 1 ≤ j ≤ p, represents the j th coordinates in the vectors (points) n i .Some of the coordinates, v j , in these vectors may be linearly dependent upon others.To simplify the problem, we first identify such dependencies and compute a set of linear equalities that expresses them (L in line 4).To do so, we consider a matrix N q×p , where the i th row consists of n T i .The j th column in N , denoted N * j , corresponds to the j th coordinate, v j .The rank of N is the number of linearly independent columns (and rows).The other columns (coordinates) can be expressed by linear combinations of the linearly independent ones.To compute these linear combinations we use the kernel of [N ; 1] (N appended with a column vector of 1's), which is the set of all vectors y such that [N ; 1] • y = 0, where 0 is the zero vector.Let B = kernel([N ; 1]) be a basis for the kernel of [N ; 1].Then |B| = p − rank(N ), and for each vector y ∈ B, the linear equality in all the rows of N (i.e., all the given vectors satisfy it).We accumulate these equalities, which capture the linear dependencies between the coordinates, in L. Further, the equalities are used to compute rank(N ) coordinates (columns in N ) that are linearly independent and, modulo L, uniquely determine the remaining coordinates.We denote by v L ↓ the subset of v that consists of the linearly independent coordinates.We further denote by n L ↓ i the projection of n i to these coordinates and by N L ↓ the projection of N to the corresponding columns.We have that , for which kernel( Next, we compute the convex closure of (v ), and conjoin it with L to obtain H, the convex closure of ( (v = n i )).
If the dimension of v L ↓ is one, as is the case in the example above, convex closure, C, of (v If the dimension of v L ↓ is greater than one, just computing the bounds of one of the constants is not sufficient.Instead, we use the concept of syntactic convex closure from [2] to compute the convex closure of (v L ↓ = n L ↓ i ) as ∃α.C where α is a vector that consists of q fresh rational variables and C is defined as follows (line 8): To illustrate the syntactic convex closure, consider a second example with a set of cubes: S = {(x ≤ 0∧y ≤ 6), (x ≤ 6∧y ≤ 0), (x ≤ 5∧y ≤ 5)}.The coefficient matrix A, and the numeral matrix N are then: A = [ 1 0 0 1 ] and N = 0 6 6 0 5 5 . Here, kernel([N ; 1]) is empty -all the columns are linearly independent, hence, L = true and v L ↓ = v.Therefore, syntactic convex closure is applied to the full matrix N , resulting in The convex closure of (v = n i ) is then L ∧ ∃α.C, which is ∃α.C here.Divisibility constraints.Inductive invariants for verification problems often require divisibility constraints.We, therefore, use such constraints, denoted D, to obtain a stronger over-approximation of (v = n i ) than the convex closure.To add a divisibility constraint for v j ∈ v L ↓ , we consider the column N L ↓ * j that corresponds to v j in N L ↓ .We find the largest positive integer d such that each integer in N L ↓ * j leaves the same remainder when divided by d; namely, there exists 0 ≤ r < d such that n mod d = r for every n ∈ N L ↓ * j .This means that d | (v j − r) is satisfied by all the points n i .Note that such r always exists for d = 1.To avoid this trivial case, we add the constraint d | (v j − r) only if d = 1 (line 12).We repeat this process for each v j ∈ v L ↓ .
In Example 1, all the elements in the (only) column of the matrix N L ↓ , which corresponds to v 1 , are divisible by 2, and no larger d has a corresponding r.Thus, line 12 of Alg. 3 adds the divisibility condition (2 | v 1 ) to D. Eliminating existentially quantified variables using MBP.By combining the linear equalities exhibited by N , the convex closure of N L ↓ and the divisibility constraints on v, we obtain ∃α.L ∧ C ∧ D as an over-approximation of (v = n i ).Accordingly, ∃v.∃α.ψ, where ψ = (A 13).In order to get a LIA cube that overapproximates S, it remains to eliminate the existential quantifiers.Since quantifier elimination is expensive, and does not necessarily generate convex formulas (cubes), we approximate it using MBP.Namely, we obtain a cube ϕ that under-approximates ∃v.∃α.ψ by applying MBP on ψ and a model M 0 |= ψ.We then use an SMT solver to drop literals from ϕ until it over-approximates ∃v.∃α.ψ, and hence also S (lines 16 to 19).The result is returned by Subsume as an over-approximation of S.
Models M 0 that satisfy ψ and do not satisfy any of the cubes in S are preferred when computing MBP (line 14) as they ensure that the result of MBP is not subsumed by any of the cubes in S.
Note that the α are rational variables and v are integer variables, which means we require MBP to support a mixture of integer and rational variables.To achieve this, we first relax all constants to be rationals and apply MBP over LRA to eliminate α.We then adjust the resulting formula back to integer arithmetic by multiplying each atom by the least common multiple of the denominators of the coefficients in it.Finally, we apply MBP over the integers to eliminate v.
Considering Example 1 again, we get that where U = {x, y}.Having such a cluster is an indication that attempting to block ϕ in full with a single lemma may require to track non-linear correlations between the constants, which is impossible to do in LIA.In such cases, we identify the coupling of the constants in U in POBs (and hence in lemmas) as the potential source of non-linearity.Hence, we concretize (strengthen) ϕ into a POB γ where the constants in U are no longer coupled to any other constant.
Coupling.Formally, constants u and v are coupled in a cube c, denoted u c v, if there exists a literal lit in c such that both u and v appear in lit (i.e., their coefficients in lit are non-zero).For example, x and y are coupled in x + y ≤ 0 ∧ z ≤ 0 whereas neither of them are coupled with z.A constant u is said to be isolated in a cube c, denoted ISO(u, c), if it appears in c but it is not coupled with any other constant in c.In the above cube, z is isolated.
Concretization by decoupling.Given a POB ϕ (a cube) and a cluster L, Alg. 4 presents our approach for concretizing ϕ by decoupling the constants in U -those that have variables as coefficients in the pattern of L (line 2).Concretization is guided by a model M |= ϕ ∧ L, representing a part of ϕ that is not yet blocked by the lemmas in L (line 3).Given such M , we concretize ϕ into a model-preserving under-approximation that isolates all the constants in U and preserves all other couplings.That is, we find a cube γ, such that Note that γ is not blocked by L since M satisfies both L and γ.For example, if Alg. 4 computes such a cube γ by a point-wise concretization of the literals of ϕ followed by the removal of subsumed literals.Literals that do not contain constants from U remain unchanged.A literal of the form lit = t ≤ b, where t = i n i x i (recall that every literal in LIA −div can be normalized to this form), that includes constants from U is concretized into a cube by (1) isolating each of the summands n i x i in t that include U from the rest, and (2) for each of the resulting sub-expressions creating a literal that uses its value in M as a bound.Formally, t is decomposed to s + xi∈U n i x i , where s = xi ∈U n i x i .The concretization of lit is the cube where M [t ] denotes the interpretation of t in M .Note that γ lit ⇒ lit since the bounds are stronger than the original bound on t: M This ensures that γ, obtained by the conjunction of literal concretizations, implies ϕ.It trivially satisfies the other conditions of Eq. (1).
For example, the concretization of the literal (x + y ≤ 0) with respect to U = {y} and M = [x = 0, y = 0, z = 1] is the cube x ≤ 0 ∧ y ≤ 0. Applying concretization in a similar manner to all the literals of the cube ϕ = (x+y ≤ 0)∧(x−y ≤ 0)∧(x+z ≥ 0) from the previous example, we obtain the concretization x ≤ 0 ∧ 0 ≤ y ≤ 0 ∧ x + z ≥ 0. Note that the last literal is not concretized as it does not include y.

Conjecture rule for LIA
The Conjecture rule (see Alg. 2) takes a set of lemmas L and a POB ϕ ≡ α ∧ β such that all lemmas in L block β, but none of them blocks α, where α does not include any known reachable states.It returns α as a new POB.
For LIA, Conjecture is applied when the following conditions are met: (1) the POB ϕ is of the form ϕ 1 ∧ ϕ 2 ∧ ϕ 3 , where ϕ 3 = (n T • x ≤ b), and ϕ 1 and ϕ 2 are any cubes.The sub-cube ϕ 1 ∧ ϕ 2 acts as α, while the sub-cube ϕ 2 ∧ ϕ 3 acts as β.(2) The cluster , where b i > b and bg ⇒ ¬ϕ 2 .This means that each of the lemmas in L blocks β = ϕ 2 ∧ ϕ 3 , and they may be ordered as a sequence of increasingly stronger lemmas, indicating that they were created by trying to block the POB at different levels, leading to too strong lemmas that failed to propagate to higher levels.(3) The formula (bg and (4) U ⇒ ¬(ϕ 1 ∧ ϕ 2 ), that is, no state in ϕ 1 ∧ ϕ 2 is known to be reachable.If all four conditions are met, we conjecture α = ϕ 1 ∧ ϕ 2 .This is implemented by CONJECTURE, that returns α (or ⊥ when the pre-conditions are not met).

Putting it all together
Having explained the implementation of the new rules for LIA, we now put all the ingredients together into an algorithm, GSPACER.In particular, we present our choices as to when to apply the new rules, and on which clusters of lemmas and POBs.As can be seen in Sec. 5, this implementation works very well on a wide range of benchmarks.
Alg. 5 presents GSPACER.The comments to the right side of a line refer to the abstract rules in Alg. 1 and 2. Just like SPACER, GSPACER iteratively computes predecessors (line 10) and blocks them (line 14) in an infinite loop.Whenever a POB is proven to be reachable, the reachable states are updated (line 38).If Bad intersects with a reachable state, GSPACER terminates and returns UNSAFE (line 12).If one of the frames is an inductive invariant, GSPACER terminates with SAFE (line 20).
When a POB ϕ, i is handled, we first apply the Concretize rule, if possible (line 7).Recall that CONCRETIZE (Alg.4) takes as input a cluster that partially blocks ϕ and has a non-linear pattern.To obtain such a cluster, we first find, using C pob ( ϕ, i ), a cluster , where k ≤ i, that includes some lemma (from frame k) that blocks ϕ; if none exists, L 1 = ∅.We then filter out from L 1 lemmas that completely block ϕ as well as lemmas that are irrelevant to ϕ, i.e., we obtain L 2 by keeping only lemmas that partially block ϕ.We apply CONCRETIZE on π 1 , L 2 to obtain a new POB that under-approximates ϕ if (1) the remaining sub-cluster, L 2 , is non-empty, (2) the pattern, π 1 , is non-linear, and (3) L 2 ∧ ϕ is satisfiable, i.e., a part of ϕ is not blocked by any lemma in L 2 .

Evaluation
We have implemented5 GSPACER (Alg.5) as an extension to SPACER.To reduce the dimension of a matrix (in SUBSUME, Sec.4.3), we compute pairwise linear dependencies between all pairs of columns instead of computing the full kernel.This does not necessarily reduce the dimension of the matrix to its rank, but, is sufficient for our benchmarks.We have experimented with computing the full kernel using SageMath [25], but the overall performance did not improve.Clustering is implemented by anti-unification.LIA terms are normalized using default Z3 simplifications.Our implementation also supports global generalization for non-linear CHCs.We have also extended our work to the theory of LRA.We defer the details of this extension to an extended version of the paper.
To evaluate our implementation, we have conducted two sets of experiments 6 .All experiments were run on Intel E5-2690 V2 CPU at 3GHz with 128GB memory with a timeout of 10 minutes.First, to evaluate the performance of local reasoning with global guidance against pure local reasoning, we have compared GSPACER with the latest SPACER, to which we refer as the baseline.We took the benchmarks from CHC-COMP 2018 and 2019 [10].We compare to SPACER because it dominated the competition by solving 85% of the benchmarks in CHC-COMP 2019 (20% more than the runner up) and 60% of the benchmarks in CHC-COMP 2018 (10% more than runner up).Our evaluation shows that GSPACER outperforms SPACER both in terms of number of solved instances and, more importantly, in overall robustness.
Second, to examine the performance of local reasoning with global guidance compared to solely global reasoning, we have compared GSPACER with an ML-based data-driven invariant inference tool LINEARARBITRARY [28].Compared to other similar approaches, LINEARARBITRARY stands out by supporting invariants with arbitrary Boolean structure over arbitrary linear predicates.It is completely automated and does not require user-provided predicates, grammars, or any other guidance.For the comparison with LINEARARBITRARY, we have used both the CHC-COMP benchmarks, as well as the benchmarks from the artifact evaluation of [28].The machine and timeout remain the same.Our evaluation shows that GSPACER is superior in this case as well.Comparison with SPACER.Table 1 summarizes the comparison between SPACER and GSPACER on CHC-COMP instances.Since both tools can use a variety of interpolation strategies during lemma generalization (Line 45 in Alg.5), we compare three different configurations of each: bw and fw stand for two interpolation strategies, backward and forward, respectively, already implemented in SPACER, and sc stands for turning interpolation off and generalizing lemmas only by subset clauses computed by inductive generalization.
Any configuration of GSPACER solves significantly more instances than even the best configuration of SPACER.Fig. 2 provides a more detailed comparison between the best configurations of both tools in terms of running time and depth of convergence.There is no clear trend in terms of running time on instances solved by both tools.This is not surprising -SMT-solving run time is highly non-deterministic and any change in strategy has a significant impact on performance of SMT queries involved.In terms of depth, it is clear that GSPACER converges at the same or lower depth.The depth is significantly lower for instances solved only by GSPACER.Moreover, the performance of GSPACER is not significantly affected by the interpolation strategy used.In fact, the configuration sc in which interpolation is disabled performs the best in CHC-COMP 2018, and only slightly worse in CHC-COMP 2019!In comparison, disabling interpolation hurts SPACER significantly.
Fig. 3 provides a detailed comparison of GSPACER with and without interpolation.Interpolation makes no difference to the depth of convergence.This implies that lemmas that are discovered by interpolation are discovered as efficiently by the global rules of GSPACER.On the other hand, interpolation significantly increases the running time.Interestingly, the time spent in interpolation itself is insignificant.However, the lemmas produced by interpolation tend to slow down other aspects of the algorithm.Most of the slow down is in increased time for inductive generalization and in computation of predecessors.The comparison between the other interpolation-enabled strategy and GSPACER (sc) shows a similar trend.Comparison with LINEARARBITRARY.In [28], the authors show that LINEARARBI-TRARY, to which we refer as LARB for short, significantly outperforms SPACER on a curated subset of benchmarks from SV-COMP [24] competition.
At first, we attempted to compare LARB against GSPACER on the CHC-COMP benchmarks.However, LARB did not perform well on them.Even the baseline SPACER has outperformed LARB significantly.Therefore, for a more meaningful comparison, we have also compared SPACER, LARB and GSPACER on the benchmarks from the artifact evaluation of [28].The results are summarized in Table 2.As expected, LARB outperforms the baseline SPACER on the safe benchmarks.On unsafe benchmarks, SPACER is Global invariant inference.An alternative to inferring lemmas for the inductive invariant by blocking counterexamples is to enumerate the space of potential candidate invariants [15,28,16,14,9].This does not suffer from the pitfall of local reasoning.However, it is only effective when the search space is constrained.While these approaches perform well on their target domain, they do not generalize well to a diverse set of benchmarks, as illustrated by results of CHC-COMP and our empirical evaluation in Sec. 5. Locality in SMT and IMC.Local reasoning is also a known issue in SMT, and, in particular, in DPLL(T) (e.g., [22]).However, we are not aware of global guidance techniques for SMT solvers.Interpolation-based Model Checking (IMC) [20,21] that uses interpolants from proofs, inherits the problem.Compared to IMC, the propagation phase and inductive generalization of IC3 [7], can be seen as providing global guidance using lemmas found in other parts of the search-space.In contrast, GSPACER magnifies such global guidance by exploiting patterns within the lemmas themselves.IC3-SMT-based Model Checkers.There are a number of IC3-style SMT-based infinite state model checkers, including [18,17,11].To our knowledge, none extend the IC3-SMT framework with a global guidance.A rule similar to Subsume is suggested in [26] for the theory of bit-vectors and in [4] for LRA, but in both cases without global guidance.In [4], it is implemented via a combination of syntactic closure with interpolation, whereas we use MBP instead of interpolation.Refinement State Mining in [3] uses similar insights to our Subsume rule to refine predicate abstraction.

Conclusion and Future Work
This paper introduces global guidance to mitigate the limitations of the local reasoning performed by SMT-based IC3-style model checking algorithms.Global guidance is necessary to redirect such algorithms from divergence due to persistent local reasoning.To this end, we present three general rules that introduce new lemmas and POBs by taking a global view of the lemmas learned so far.The new rules are not theory-specific, and, as demonstrated by Alg. 5, can be incorporated to IC3-style solvers without modifying existing architecture.We instantiate, and implement, the rules for LIA in GSPACER, which extends SPACER.
Our evaluation shows that global guidance brings significant improvements to local reasoning, and surpasses invariant inference based solely on global reasoning.More importantly, global guidance decouples SPACER's dependency on interpolation strategy and performs almost equally well under all three interpolation schemes we consider.As such, using global guidance in the context of theories for which no good interpolation procedure exists, with bit-vectors being a primary example, arises as a promising direction for future research.

Fig. 1 (Fig. 1 :
Fig. 1: Verification tasks to illustrate sources of divergence for SPACER.The call nd() non-deterministically returns a Boolean value.

Table 1 :
Comparison between SPACER and GSPACER on CHC-COMP.